Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2018-6605
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RISK
open
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open
ReferênciaVexDay Proof
Pragyan CMS 2.6.4 - Multiple SQL Injections
CVE-2009-1480webappsphp
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open
Referência
CVE-2015-7243
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RISK
open
ReferênciaVexDay Proof
phpRealty 0.02 - 'MGR' Multiple Remote File Inclusions
CVE-2007-4834webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP cod
35RISK
open
Referência
CVE-2019-6111
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISK
open
Referência
CVE-2009-2485
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a
50RISK
open
Referência
CVE-2017-8618
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server
35RISK
open
Referência
CVE-2012-4177
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -
50RISK
open
Referência
CVE-2025-2746
CVE-2025-2746CRITICALunder attack
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
100RISK
open
Referência
CVE-2025-2746
CVE-2025-2746CRITICALunder attack
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
100RISK
open
Referência
CVE-2021-46381
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RISK
open
Referência
CVE-2022-30075
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1487webappsphp
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
eNetman 20050830 - 'index.php' Remote File Inclusion
CVE-2007-4712webappsphp
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code
35RISK
open
ReferênciaVexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
CVE-2008-0437remotewindows
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RISK
open
Referência
CVE-2018-12634
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo
50RISK
open
Referência
CVE-2019-10475
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RISK
open
Referência
CVE-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
Referência
CVE-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RISK
open
Referência
CVE-2016-3078
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia
35RISK
open
Referência
CVE-2017-1000170
jqueryFileTree 2.1.5 and older Directory Traversal
50RISK
open
Referência
CVE-2011-4722
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RISK
open
Referência
CVE-2014-2850
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1488webappsphp
Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
Adobe Reader 8.1.4/9.1 - 'GetAnnots()' Remote Code Execution
CVE-2009-1492remotelinux
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RISK
open
Referência
CVE-2018-14847
CVE-2018-14847CRITICALunder attack
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
Referência
CVE-2017-0101
CVE-2017-0101HIGHunder attackransomware
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7
83RISK
open
previouspage 283 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.